Tools to learn for SOC Analysts

Поділитися
Вставка
  • Опубліковано 29 вер 2024

КОМЕНТАРІ • 43

  • @thefrub
    @thefrub 10 місяців тому +11

    SANS needs to hire this man! You have a really concise yet entertaining way of presenting, keep it up!

    • @MyDFIR
      @MyDFIR  10 місяців тому +1

      Haha thank you for the kind words!

  • @RandyAinsworth-tx6vn
    @RandyAinsworth-tx6vn 9 місяців тому +1

    Wireshark and splunk and suricata for ips and some through thm

    • @MyDFIR
      @MyDFIR  9 місяців тому +1

      Great choice of tools!

    • @RandyAinsworth-tx6vn
      @RandyAinsworth-tx6vn 9 місяців тому

      @@MyDFIR but so many tools. Which best ips ids would be best suricata or solarwinds. Edr croudstrik or … lol but job wise learn splink and witeshark and see what ips ids and edr the company uses

    • @MyDFIR
      @MyDFIR  9 місяців тому +1

      @@RandyAinsworth-tx6vn Agreed which is why at the end of the day, a tool is just a tool. Understand the use case and pick one that fits the business budget. As long as a tool can provide visibility, have logging and ability to search within the tool. That is a good tool. To make it a great tool, have responsive capabilities.

  • @ADITYA_1303
    @ADITYA_1303 Місяць тому

    ❤❤❤❤❤

  • @RubenMuñozAragon-e9n
    @RubenMuñozAragon-e9n 9 місяців тому +1

    Gracias por todo el contenido
    Nos ayuda mucho a la comunidad de Seguridad defensiva Blue Team. Normalmente en las Redes hay poca informacion.
    Un abrazo.

  • @TheAshleyone
    @TheAshleyone 10 місяців тому +1

    ❤❤❤❤❤

  • @dreamwilder
    @dreamwilder 6 місяців тому

    Is a lab something I can download to my computer? What labs do you use for a windows based system?

    • @MyDFIR
      @MyDFIR  6 місяців тому +1

      Yeah you can, or you can use sites like cyberdefenders, blue team level one, letsdefend and many others.

  • @abdoabdo-mj2hp
    @abdoabdo-mj2hp 7 місяців тому +1

    Bro great job a lot important info

    • @MyDFIR
      @MyDFIR  7 місяців тому

      Thanks a lot!

  • @gabegutz7120
    @gabegutz7120 7 місяців тому +1

    Kind of surprised to hear Arkime mentioned lol. My uncle helped develop the tool and the Cont3xt tool used within Arkime

    • @MyDFIR
      @MyDFIR  7 місяців тому +1

      Wow! Thats amazing. Arkime is great, it is one of those tools you never thought you needed until you use it haha - Indexed PCAPs ....beautiful

  • @irocz5150
    @irocz5150 10 місяців тому +1

    Great content. No Tools will cover everything...and are not 100% perfect. You are right when you mention a SIEM is no required...now we have hyperautomation as a "new" trend SIEM killer. Sometimes tools go hand 2 hand with required compliance like hippa, gdpr etc etc.

    • @MyDFIR
      @MyDFIR  10 місяців тому +1

      Yup, “No Tools will cover everything” love it. ❤️

  • @Marilyn_ken
    @Marilyn_ken 8 місяців тому +1

    Thanks for this video.. Been on ur page all night, this the answer I have been looking for

    • @MyDFIR
      @MyDFIR  8 місяців тому

      Happy to help! Thanks for watching ❤️ let me know if you have any questions!

  • @joshuaspeshock4636
    @joshuaspeshock4636 10 місяців тому +2

    Really like how you not only covered tools but resources that you can use to get more hands on practice with them whether it’s through investigations or home labs. Also, liked how you brought up the context of it’s great to know the tools but it’s more important to understand the value behind them and when is best to use them. Overall, great explanations and really well done great job!

    • @MyDFIR
      @MyDFIR  10 місяців тому +1

      Thanks! It’s always about the value, really understanding the WHY use a certain tool and how it functions.

  • @addey6323
    @addey6323 10 місяців тому +1

    Calmly waiting for a piece on tool for digital forensic/eDiscovery. Thanks for sharing. Been watching from Ghana 🇬🇭 West Africa

    • @MyDFIR
      @MyDFIR  10 місяців тому +1

      Soon 👀 will do a lot more DFIR related videos in the new year

  • @TheSilentLearner786
    @TheSilentLearner786 10 місяців тому +1

    Sir plz do tutorial videos related python for cybersecurity

    • @MyDFIR
      @MyDFIR  10 місяців тому +1

      Anything specific you want to know? Thanks for the suggestion!

    • @estebangodoy386
      @estebangodoy386 6 місяців тому

      ​@@MyDFIRforensics or threat intelligence gathering with Python would be awesome 💯

  • @melaronvalkorith1301
    @melaronvalkorith1301 10 місяців тому +1

    Great video! I appreciate how you call out the fact that tools are only as good as what you use them for. I’d love to see a video about your way (or various ways you know) of approaching an investigation and the thought process that goes into each step. Keep up the great work!

    • @MyDFIR
      @MyDFIR  10 місяців тому

      Thanks! I have something similar coming out which is going through a PCAP. I do like the idea of talking about the thought process. Great suggestion ❤️

  • @b3rn4rd01
    @b3rn4rd01 10 місяців тому +1

    ❤❤❤❤❤❤❤❤
    Awesome SOC info!!!!

    • @MyDFIR
      @MyDFIR  10 місяців тому

      Thank you!!

  • @mrgolbez
    @mrgolbez 10 місяців тому +1

    ❤❤❤ best SOC info out there!

    • @MyDFIR
      @MyDFIR  10 місяців тому

      Wow, thanks!

    • @Brantley_ZA
      @Brantley_ZA 10 місяців тому

      Facts! 🔥

  • @elliscaicedo9045
    @elliscaicedo9045 7 місяців тому +1

    thanks for you content bro

    • @MyDFIR
      @MyDFIR  7 місяців тому

      My pleasure

  • @iamrestnpieces
    @iamrestnpieces 10 місяців тому

    Your "Next Steps" page for your mentorship is asking for additional information but there are no input fields. Update: I just received an email. I will respond that way.

    • @MyDFIR
      @MyDFIR  10 місяців тому

      Awesome! Thanks for signing up, I’ll go over my emails soon ❤️

  • @SamuelDarko-ql5ov
    @SamuelDarko-ql5ov 9 місяців тому

    You are very good at what you do, and I want to be a SOC Analyst any mentorship available? Please help me.

    • @MyDFIR
      @MyDFIR  9 місяців тому

      Yeah! Feel free to sign up on my site mydfir.com

  • @Kiran_gowda_kar
    @Kiran_gowda_kar 10 місяців тому

    Sir can u please suggest some laptop configurations along with laptop brand for learning and practsing Cybersecurity.

    • @MyDFIR
      @MyDFIR  10 місяців тому

      Great question, for laptops you really need about 16GB+ RAM and the more the better. I don’t really have a particular brand I recommend, however a lot of my laptops (current & previous) are MSI laptops used for gaming. 😂

    • @Kiran_gowda_kar
      @Kiran_gowda_kar 10 місяців тому

      @@MyDFIR Thanks for the Replay sir and can u please share the link of laptop u have currently (MSI laptop link) please kindly share sir

    • @Kiran_gowda_kar
      @Kiran_gowda_kar 10 місяців тому

      Which graphics card is better NVidia or iris